How to Build an AI Governance Committee: Roles, Charter, and Steps

AN
AI Navigator Collective

When you talk to a small business owner about an ‘AI governance committee’, the picture that occurs to them is generally one that applies to a bank—with a legal department on every floor and a room full of vice presidents. It doesn’t have to be like that. For a business of your size, it could be as small as three or five people, need only one two-page document, and take up one hour a month.

The figure that should concern you is that, as DigitalApplied’s analysis shows, 77% of small businesses that currently use AI have no written AI policy and only about 2% have something that can be described as a mature governance framework. You are most likely already operating AI without being aware of it; around three out of four small businesses make use of it via features that are already included in the tools they already pay for such as the CRM, the inbox, and the help desk.

The risk lies in the gap between employing AI and having actual control over it; it is a small, multidisciplinary committee that fills this gap. This committee establishes the rules according to which your business adopts AI, approves the more risky applications, and maintains a record of who made each decision. If it is carried out properly, it does not hinder progress since it provides your team with a clear route to approval, outperforming the present situation in which it is unclear what is permitted.

The guide shows how to set up one without having to deal with the complexities associated with enterprise systems: it outlines the roles that are necessary, provides a charter that you can use as a template, explains how the meetings should be conducted, and includes a practical 90-day plan.

Key takeaways

  • An AI governance committee is a group drawn from a variety of different functions; its responsibilities include setting AI policy, approving use cases, and monitoring for risk. It does not involve a full-time commitment and should not be regarded as an IT project board.
  • At that scale involving small and medium businesses, three to five people are responsible for all aspects. The floor has a sponsor who possesses real authority, an operations owner, and a person who is accountable for data and security.
  • You will probably need one if the AI that you use interacts with customers, is involved in making decisions about people, deals with sensitive data, or is sold to customers in the EU or to enterprise customers.
  • A charter that is two pages long and has the ownership clearly stated is better than a 30-page draft which no one opens.
  • Begin with the free NIST AI Risk Management Framework and hold onto the ISO/IEC 42001 certification until a customer or a regulator actually requests it.
  • The EU’s AI Act may affect American companies, and you will be held responsible for what your AI tells your customers. Air Canada discovered this in a court case.

What an AI governance committee actually is (and isn’t)

The group is small and consists of people drawn from various parts of the business, deciding together on the way the company should use AI responsibly. There are only three roles: to establish the policies, to approve or reject particular AI applications, and to continue monitoring for risk over time.

It is not a group of new full-time employees, not an approval board for all IT activities, and not a permanent “no” machine; in fact, the whole idea is the exact opposite, since it provides the team with a quick and predictable means of adopting useful tools without having to create a mess later on.

It is useful to consider the committee in the context of the other ideas surrounding it. AI governance is the general field concerned with directing the way your organization uses AI. The committee is the entity that carries out this role: it serves as the means of achieving responsible AI (that is, using AI in a way that is consistent with your values), AI risk management (involves identifying and reducing harm), AI compliance (ensuring that laws and standards are met), AI ethics (concerned with fairness and honesty), AI transparency (involving informing people when AI is being used), and AI security (involving the protection of your data). For the wider view, our overview of AI governance explains how these various elements are connected.

The difference between a committee, a steering committee and board oversight

They are always confused. The steering committee is responsible for setting the strategy and the budget. The governance committee is in charge of policy, risk, and compliance. And the board, if there is one, gives the necessary top-level oversight and approval.

At small scale this tends to result in a single small group, and that’s acceptable; there’s no need to have three bodies when one is enough.

First of all, do you really need one?

Act honestly when you are establishing anything; it isn’t necessary for every business to have a standing committee from the very beginning.

You likely need one if any of these are true:

  • You run AI that talks to customers. This includes a chatbot on your website, email replies written by AI, and an AI agent that answers calls.
  • The use of AI involves making important decisions regarding people’s hiring, lending, or credit eligibility and pricing, all of which have an impact on access.
  • You are dealing with regulated or sensitive data, such as that relating to health, finance, biometrics, or information about children.
  • You either sell to customers in the EU or you deal with larger companies that submit vendor security and AI questionnaires.
  • You are operating a number of AI tools beyond a few, or members of the staff are using tools that were never approved, a situation frequently referred to as shadow AI.
  • You’ve already experienced a near-miss when you gave a customer the wrong answer or when someone pasted sensitive data into a public chatbot.

If none of the above still applies, then try a lighter approach by naming one AI champion and drawing up a one-page acceptable-use policy. You can use our collection of examples of AI governance policy examples to give you a head start. Revisit the committee question six months later.

A major reason why the bar is lower than most people think is that you are liable for what your AI says. In the case of Moffatt v. Air Canada from 2024, a Canadian tribunal made the airline liable since its customer support chatbot had given the customer incorrect information regarding bereavement fares and had simply dismissed the claim that the chatbot should be considered a ‘separate legal entity’ responsible for its own actions. Although the amount of damages was minor, amounting to about C$812, the ruling sets a precedent that applies to any business that operates a bot making promises.

Step 1: Define the committee’s purpose and scope

Begin with a brief mandate, perhaps two or three sentences. Link it to a business objective, not merely to risk: “The purpose of this committee is to enable us to adopt AI quickly and safely by establishing clear rules, examining higher-risk applications, and keeping a record of our decisions.”

Treat it as something that enables and you’ll see how your team’s attitude towards it shifts. A committee which only blocks is ignored, while one which unblocks is put to use.

First, work out for yourself what constitutes ‘AI’ and make your definition as broad as possible; this should include any tool that makes predictions, suggestions, produces content, or reaches decisions, so covering AI features that are already present in the software you use, such as lead scoring in your CRM, smart replies in email, ticket routing in the help desk, and meeting summaries from your video calls.

List everything that is outside the scope. The committee is responsible for AI, not for all areas of IT. Stating this at the beginning prevents the gradual shift towards general technology governance which silently undermines these groups.

Step 2: Choose the right people (think roles, not headcount)

Nine executives don’t have to be present, since six different points of view are enough and a single person can take on more than one of these.

  1. The leader or executive sponsor is responsible for providing the necessary authority and funding. This is a hard requirement; in its absence the committee can at best be given an advisory role.
  2. Legal, compliance, and risk matters—contracts, liability, and regulatory exposure.
  3. Data, security, and IT issues—where data is going, who has access to it, and the security of the vendors.
  4. The business or operations side—the people who will actually use the AI and feel any friction it causes.
  5. People or HR. Anything that involves employees, hiring, or tracking.
  6. A voice that is technical and knowledgeable about AI; someone who understands the limitations of models, the issue of bias, and the phenomenon of hallucinations.

How to cover six perspectives with three to five people

Here’s the multi-hat map most SMBs land on:

Owner / General Manager Executive sponsor + business
Operations or office manager Operations + people/HR
IT lead or your managed-service provider contact Data, security, and IT
Outside attorney or fractional advisor (on call) Legal + technical/AI

You must have three members of the committee at the very least: a sponsor who has real authority, an operations owner, and a person who is responsible for data and security; all the others are contributors that you can bring in when required.

Is a Chief AI Officer necessary? In most cases, no, since having a named executive sponsor together with an optional fractional or external advisor is more beneficial than appointing a new member of the C-suite. Make sure that the voting group remains small and consists of an odd number so that decisions won’t be delayed.

Step 3: Write a lean charter (template inside)

Write a lean charter (template inside)

A charter is the brief document that confers legitimacy on your committee; the rule to follow is that a two-page charter with clearly named owners is better than a 30-page draft that no one reads. There is no need to wait for a perfect enterprise framework.

A solid SMB charter needs seven short sections:

  1. Objective: the instruction you received in Step 1.
  2. Determine the scope of the AI, including that which is embedded or purchased.
  3. The names of the members and their roles, the different perspectives included, and who votes.
  4. Decision rights what must come to the committee and what the teams can approve.
  5. A three-tier system of risk assessment (more detailed below).
  6. Rules regarding operation: how often meetings are held, what quorum is required, and the way decisions are recorded.
  7. You should have a review at least once every year, but more frequently if there are changes in the way you use AI or in the law.

Copy-and-paste charter skeleton

v1.0 Charter of the [Company] AI Governance Committee · Review date: [date]

  1. PURPOSE

We assist [Company] in making a quick and safe transition to AI by establishing rules, examining those applications that involve a higher level of risk, and keeping a record of our decisions.

  1. SCOPE

We cover all the AI that we build, purchase or use, as well as the AI features contained in existing software. It does not include general IT issues that are unrelated to AI.

  1. MEMBERS & ROLES

Sponsor: [name] · Operations: [name] · Data/Security: [name]

On call: [legal/advisor] · Voting members: [names]

  1. DECISION RIGHTS

It is brought before the committee if it is an AI that interacts with customers; if it uses personal data; if it costs more than $[X] per year; or if it is considered ‘high-risk’ (see §5).

Teams approve themselves if the task is low-risk, internal, and does not involve personal data.

  1. RISK TIERS

If the request is low then it gets a fast track; if it’s medium then it receives a light review; and if it’s high then it is given a full review plus mandatory human supervision.

  1. OPERATING RULES

There is a monthly meeting that lasts 60 minutes; the quorum required is 50% plus one; decisions are taken by a majority vote; all decisions are recorded in the AI inventory.

  1. REVIEW

It is reviewed each year, or more quickly if there are changes to our AI footprint or to the law.

It’s a good idea to keep the complete editable version available since most teams provide it as a download and then improve it after the first month. If you want to explore deeper structural patterns, refer to our guide on building an AI governance framework.

Step 4: Set up how the committee runs

A charter serves as a rulebook, and this stage is the routine that brings it to reality.

Have a meeting once a month lasting sixty minutes—that’s enough to begin with. For low-risk requests, include asynchronous approvals in between so that you aren’t the bottleneck. Do not adopt the enterprise approach of holding quarterly boards together with weekly working groups since that approach is too cumbersome for your size.

For intake and risk tiering, use a brief form for any new AI tool or use case—specifying what it does, what data it involves, whether it is customer-facing, and who is responsible for it—then route it according to the tier.

Low Internal, no personal data (e.g., drafting blog ideas) Self-approve; log it
Medium Some business data, limited exposure Light review at the monthly meeting
High Customer-facing, or affects decisions about people Full review + a human stays in the loop

This layering is in fact all that practical AI risk management involves: it consists in matching the level of effort to the stakes rather than handling all the tools in the same way.

State clearly in writing that no important decision regarding a person is based solely on AI; a human must review it and has the ability to override it.

Maintain a straightforward list of AI tools. A single shared spreadsheet will suffice—within it you should include every tool and the particular use cases it serves, along with its owner, the risk level associated with it, the data it handles, and its current review status. When carrying out your first inventory, treat it as a search for any embedded or shadow AI by examining the CRM, the help desk, email systems, HR tools, marketing systems, and the security tools. This spreadsheet then serves as your response whenever a customer submits an AI questionnaire or when a regulator visits.

Step 5: Anchor your rules to a recognized framework

Do not attempt to create a system of government from scratch; instead, adopt a reliable framework so that your policies can withstand examination.

Two frameworks matter here:

What it is A voluntary risk framework from the U.S. government The first international AI management-system standard
Cost Free Paid standard + audit fees
Certifiable? No Yes (3-year certificate, annual audits)
Best for Getting started; any size Proving maturity when customers demand it

The NIST AI Risk Management Framework is based on four functions, each of which corresponds directly to the activities carried out by your committee: Govern (which includes leadership, policy-making, and accountability), Map (involving an understanding of the context and risks), Measure (concerned with tracking performance, bias, and reliability), and Manage (involving the implementation of controls and responding to problems). It is free, applicable to any sector, and can be scaled down to suit your organisation’s size, which is why it is an appropriate starting point for almost every small and medium-sized businessYou should only move to ISO/IEC 42001 when a customer, a partner, or a regulator requests third-party assurance; it is a certifiable management system belonging to the same family as ISO 27001 and provides more than most small businesses require on the first day. The OECD AI Principles serve as a values-based reference as well.ceThe discipline that counts more than the framework you choose is to avoid simply adopting it on paper; you need to adapt it to your real intake, approval, and review procedures. If patterns that have proven effective in other cases are of interest to you, refer to our responsible AI governance best practices.

Step 6: Know the rules that actually apply to you (2026 snapshot) 

A great deal of the advice currently available on the internet has now become outdated. The following should be regarded as a kind of plan, and the particular details should be checked over with professional advice since the situation is always changing.ng.

Can the EU AI Act apply to a small business in the United States? Yes it can. Its scope functions in the same way as GDPR: if you offer an AI system in the EU or if you have an effect on people there, then you will be within the scope. The official EU AI Act framework issued by the European Commission is the authoritative source.

On August 2, 2026, there will be transparency obligations (which involve disclosing when people are interacting with AI and labeling content that has been generated by AI), powers to impose penalties on providers of general-purpose AI models, and a market-surveillance authority.

The idea that ‘full enforcement of high-risk obligations will take place in August 2026’ is completely incorrect since, under the Digital Omnibus agreed upon in spring 2026, the more onerous high-risk obligations relating to the use of AI in recruitment or credit scoring, for example, were postponed until December 2, 2027 (2028 in the case of AI incorporated into regulated products).

Smaller businesses will benefit, even though most of the articles omit this point: they will have simpler documentation requirements and face reduced fines. The fines follow a “lower of” rule, meaning that the penalty is the smaller of a set amount or a percentage of turnover, so a small company will have a cap that is proportional, not the headline figure of €35 million.

In the United States there is still no all-encompassing federal AI law; although a White House executive order issued in December 2025 promotes a national strategy and asks that conflicting state regulations be resolved, state laws continue to apply at this time. Colorado repealed its first risk-based AI Act in May 2026 and substituted it with a more limited disclosure-and-rights approach which comes into effect on 1 January 2027. Don’t forget to keep an eye on California, Texas, Utah, and Illinois as well.

The practical approach is to define each AI use case once, assign it to the relevant rules, and obtain legal advice for any situation that is high-risk or has significant consequences.

Your first 90 days: a realistic timeline

Your first 90 days a realistic timeline

It’s not necessary to have all the features on day one; instead, proceed step by step, beginning with the AI that poses the greatest risk.

Weeks 1–2 Write the mandate; confirm your executive sponsor
Weeks 3–4 Name your 3–5 members; map the six perspectives
Weeks 5–6 Ratify the two-page charter; get leadership sign-off
Weeks 7–10 Build the AI inventory; hunt down embedded and shadow AI
Weeks 11–13 Run your first use-case review; give a short leadership update

Common mistakes that turn governance into theater

The vast majority of committees that fail do so in the same small number of ways, and each of these cases has a simple solution.

  • There is no genuine authority; the solution is to grant the committee the ability to approve, suspend, or halt AI projects.
  • There is no executive sponsor. Solution: get one in place before you begin since it is a must-have, not an optional extra.
  • The tendency for the project to expand into general IT should be avoided; the solution is to stick to the AI charter and eliminate any deviation during the annual review.
  • One-time charter. Solution: arrange for a yearly review and initiate an update each time there is a change in your use of AI or in the law.
  • There’s a policy with no enforcement mechanism; the solution is to link the charter to your actual intake and approval process, not to a forgotten shared drive.
  • It’s too heavy, which is why people go around it. Solution: make the fast lane for low-risk cases actually fast; if the regulatory process is slower than just ignoring it, then the team will choose to ignore it.

For additional examples of patterns that work in practice, our corporate AI governance best practices examine each one in more detail.

How to tell if it’s working

A dashboard isn’t necessary; plain signals show you that the committee is earning its hourly quota each month.

  • Time to approval for low-risk tools takes days, not weeks.
  • Try to include all AI tools.
  • Any problems identified before launch—such as a bias issue or a data risk found during the review process—count as a success.
  • The completion of training for staff who use AI.
  • Charter reviewed on schedule.

A future trend to plan for: AI agents

The next challenge relating to governance is already here. Agentic AI systems—which take action rather than just answering questions—are spreading rapidly. According to Deloitte’s 2026 research, about 74% of organisations plan to adopt agentic AI within two years, but only one in five has mature governance in place.

You wouldn’t need to have a separate process for this—just include two questions on your intake form at the moment: one asking what the agent can do by itself and the other asking where human approval is required before it takes action.

Frequently asked questions

How many people should be on an AI governance committee for a small business? 

Three to five is plenty. The minimum credible version is a sponsor with authority, an operations owner, and someone accountable for data and security.

Do we need to hire a Chief AI Officer? 

Usually not. For an SMB, a named executive sponsor plus an optional fractional or external advisor is more proportionate than a new C-suite role.

How is a governance committee different from a steering committee? 

A steering committee sets strategy and budget; a governance committee owns policy, risk, and oversight. Small businesses often combine the two into one group.

How often should the committee meet? 

Monthly for an hour works well, with fast asynchronous approvals for low-risk requests between meetings.

We’re a 20-person company; isn’t this overkill? 

No. Right-sized, it’s a couple of hours a month that prevent data leaks, bad client deliverables, and legal exposure, and most small firms run more AI than they realize.

What’s the difference between NIST AI RMF and ISO/IEC 42001? 

NIST AI RMF is a free, flexible framework. ISO/IEC 42001 is a certifiable standard. Start with NIST; pursue ISO only if a customer or regulator requires certification.

Does the EU AI Act apply to my US small business? 

It can, much like GDPR, if you offer AI to or affect people in the EU. Transparency duties and model-provider penalties are live from August 2026, while heavier high-risk rules were deferred to December 2027, and smaller firms get reduced fines.

How much does it cost to set up? 

You can start for $0 in tooling: a shared spreadsheet for your inventory and a two-page charter. The main cost is a few hours of people’s time each month.

Conclusion: start small, start this week

An AI governance committee at SMB scale isn’t a bureaucracy. It’s a sponsor, two or three colleagues, a two-page charter, a monthly meeting, and a spreadsheet tracking every AI tool you touch. That’s enough to protect your business and give your team a clear path to adopt AI with confidence.

The hardest part is starting, so make the first move concrete: build your AI inventory this week. List every AI tool you and your team use, including the ones hiding inside software you already pay for. Almost everything else follows from that one list.

If you want templates, peer examples, and a community working through the same questions, join the AI Navigator Collective and build your committee alongside other small and mid-sized businesses.

Stay Connected To The AI Navigator Collective

Sign Up for our newsletter.